Audit & Assurance
Medical Device Audits
Quality management system audits against ISO 13485, EU MDR, IVDR and FDA 21 CFR Part 820 for medical device manufacturers, suppliers and in vitro diagnostic developers.
Executive Overview
The medical device regulatory landscape has undergone fundamental change with the full application of EU MDR 2017/745 and the continuing transition to IVDR 2017/746. These regulations impose substantially greater requirements on manufacturers, in clinical evidence, post-market surveillance, quality management and technical documentation, than the predecessor MDD and IVDD. Organisations that approach MDR compliance as an extension of their MDD quality system frequently discover material gaps.
ISO 13485:2016 remains the internationally recognised quality management system standard for medical device manufacturers. Compliance with ISO 13485 is a prerequisite for CE marking under EU MDR and for regulatory approval in most major markets. Independent ISO 13485 audits provide manufacturers with objective assessment of their QMS against current standard requirements and common Notified Body audit focus areas.
Sthira Assure medical device audits cover the full scope of ISO 13485, EU MDR/IVDR and FDA QSR requirements, from design and development controls and risk management through to supplier qualification, production controls, post-market surveillance and vigilance reporting. We provide findings that reflect current Notified Body and regulatory authority inspection priorities.
Regulatory Frameworks
- ISO 13485:2016
- EU MDR 2017/745
- EU IVDR 2017/746
- FDA 21 CFR Part 820
- ISO 14971 (Risk Management)
- MDSAP Programme
Common Compliance Risks
EU MDR/IVDR Transition Gaps
The transition to EU MDR 2017/745 and IVDR 2017/746 continues to present significant compliance challenges. Many device manufacturers still have inadequate technical documentation, insufficient clinical evidence supporting clinical evaluation reports and incomplete post-market surveillance systems. Notified Body capacity constraints mean that organisations with documentation gaps face extended approval timelines.
Post-Market Surveillance System Weaknesses
EU MDR places substantially greater requirements on post-market surveillance than the predecessor MDD. Many organisations have PMS plans that describe surveillance activities but do not demonstrate that data collection, analysis and evaluation activities are actually being performed. Inspectors assess whether PMS outputs are generating actionable conclusions and feeding back into design and risk management.
Design and Development Controls
Traceability from user needs through design inputs, design outputs, design verification and design validation is a core ISO 13485 requirement that inspectors consistently examine in detail. Organisations that cannot demonstrate complete traceability, or where design changes have not been processed through controlled change procedures with risk assessment, face significant findings.
Clinical Evaluation Adequacy
Clinical evaluation reports under EU MDR must demonstrate clinical benefit based on clinical data, not just state of the art comparisons. Many CERs prepared under the predecessor MDD approach are inadequate under MDR standards. This is a critical gap that affects the ability of manufacturers to obtain and maintain CE marking for existing products.
Scope of Services
Common Audit Findings
These represent frequently observed findings during medical device QMS audits. They reflect gaps that independent assessment routinely identifies, particularly in organisations navigating the transition from MDD to EU MDR.
Frequently Asked Questions
What is the difference between an ISO 13485 audit and an EU MDR audit?
ISO 13485 audits assess quality management system compliance against the international standard — covering design and development, supplier controls, production, measurement and improvement. EU MDR audits assess conformity with Regulation 2017/745, including clinical evidence standards, technical documentation content, post-market surveillance and vigilance reporting. Many organisations require both: ISO 13485 certification as a QMS foundation and MDR-specific assessment of technical files and clinical evidence.
How do Notified Body audits differ from independent quality audits?
Notified Body audits are formal conformity assessment activities conducted as part of the CE marking process — they follow defined protocols and result in certification decisions. Independent quality audits are advisory — they assess the same quality systems and technical documentation against current regulatory expectations, identify gaps, and provide findings that the organisation can address before formal Notified Body assessment. Independent audit is particularly valuable as preparation for NB surveillance audits or when transitioning from MDD to MDR.
Does our organisation need an MDSAP audit?
The Medical Device Single Audit Programme (MDSAP) enables a single audit to satisfy the regulatory requirements of Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA) and the United States (FDA). Organisations seeking regulatory approval in multiple MDSAP member markets may benefit from MDSAP certification rather than separate national audits. The EU and UK are not MDSAP members, so CE marking under MDR requires separate conformity assessment.
How often should a medical device QMS be independently audited?
ISO 13485 does not specify a fixed frequency for independent external audits beyond the certification audit cycle. However, organisations undergoing MDR transition, planning product launches, operating in higher-risk device categories (Class IIb, III) or managing significant supply chain changes benefit from independent audit annually or at key programme milestones. Organisations approaching Notified Body surveillance audits should typically engage independent audit support six to twelve months in advance.
Request a Medical Device Audit
Contact our team to discuss your ISO 13485, EU MDR or FDA QSR audit requirements.